Skip to content

Comment on StartCom charges for reissuing SSL certs due to Heartbleed

Comments

Who wants to file the bug for removal from Mozilla?

http://www.mozilla.org/en-US/about/governance/policies/secur...

Section 2, dot 2.

CAs must revoke Certificates that they have issued upon the occurrence of any of the following events:

the CA obtains reasonable evidence that the subscriber’s private key (corresponding to the public key in the certificate) has been compromised or is suspected of compromise (e.g. Debian weak keys), or that the certificate has otherwise been misused;

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.